Services
Everything we do, organised by need.
From strategy to operations. From compliance to trust. 50 services across eight areas, each with its own detailed page.
I need cybersecurity leadership
Cybersecurity governance and leadership
Cybersecurity strategy, governance and leadership that turn technical and regulatory risks into executive decisions.
vCISO
External, part-time cybersecurity leadership with executive accountability.
Govern- Security master plan
- Executive dashboard
- Quarterly report to management
CISO Office
A security office that gives the in-house CISO structure, method and delivery capacity.
Govern- Project plan and tracking
- Evidence repository
- Status reports for committees
Security Committee
Design, set-up and facilitation of the cybersecurity governance body.
Govern- Committee charter
- Executive dashboard
- Minutes and resolution tracking
Risk governance
Methodology, analysis and treatment of technology risks aligned with the business.
Govern- Risk analysis report
- Risk map and risk appetite
- Prioritised treatment plan
Roadmap and executive reporting
Multi-year roadmap and executive reporting that translate security into decisions.
Govern- Cybersecurity roadmap
- Executive dashboard
- Periodic report to management
AI governance (ISO/IEC 42001 and AI Act)
Inventory, risks, evidence and maturity to use artificial intelligence with control and compliance.
Govern- AI inventory and register
- AI usage policy
- AI risk assessment
Third-party risk (TPRM)
Management of supplier and third-party risk across the entire lifecycle.
Govern- TPRM programme
- Supplier and risk register
- Assessment reports per supplier
I need to comply with regulations
Compliance and regulation
We turn regulation, continuity and AI governance into controls, owners, processes and verifiable evidence, with functionally segregated review.
Spanish National Security Framework (ENS)
Adaptation, implementation and preparation for ENS certification for public administrations and their suppliers.
Demonstrate- Categorisation report
- Statement of applicability
- Adaptation plan
NIS2
Adaptation to the NIS2 Directive for essential and important entities.
Demonstrate- Applicability report
- NIS2 gap assessment
- Adaptation plan
DORA
Digital operational resilience for financial entities and their ICT providers.
Demonstrate- DORA gap assessment
- ICT risk framework
- Provider register
ISO/IEC 27001
Implementation and certification of the information security management system.
Demonstrate- Documented ISMS
- Statement of applicability
- Internal audit report
NIST CSF and CIS Controls
Maturity assessment and improvement plan based on internationally recognised frameworks.
Demonstrate- Maturity report
- Target profile
- Prioritised improvement plan
GDPR and LSSI
Data protection and compliance with information society services regulation.
Demonstrate- Record of processing activities
- DPIA
- Legal texts and contracts
Internal audit, gap assessment and due diligence
Functionally segregated review for audits, customers, committees and corporate transactions.
Demonstrate- Audit report
- Findings and risk matrix
- Prioritised action plan
I need to protect my operations
Operations and defence (CyberOps)
Operations, monitoring, response and technological resilience to protect critical assets 24/7.
SOC
Security operations centre for continuous monitoring, detection and response.
Detect and respond- SOC service with SLA
- Response playbooks
- Monthly security report
SIEM Monitoring
Real-time collection, correlation and analysis of logs from across the entire infrastructure.
Detect and respond- Operational SIEM platform
- Use case catalogue
- Dashboards
MDR
Managed detection and response: experts who act on the threat rather than just reporting it.
Detect and respond- MDR service with response SLA
- Incident report
- Improvement recommendations
EDR / XDR and endpoint protection
Advanced protection for workstations, servers and mobile devices with detection and response at the endpoint.
Detect and respond- Deployed platform and policies
- Coverage and status report
- Response procedures
Threat Hunting
Proactive hunting for adversaries that have already evaded automated defences.
Detect and respond- Hunting campaign report
- New detection rules
- Remediation plan
Incident response
Containment, eradication and recovery from incidents, on retainer or on demand.
Detect and respond- Incident response plan
- Playbooks by incident type
- Forensic and post-incident report
Cloud Security
Security for cloud and hybrid environments: configuration, identities, workloads and data.
Detect and respond- Cloud posture report
- Hardening plan
- Reference architecture
Email Security
Email protection against phishing, malware, CEO fraud and domain spoofing.
Detect and respond- Configured protection platform
- DMARC policy at reject
- Email threat report
IAM / PAM and secure access
Identity management, strong authentication and control of privileged accounts.
Detect and respond- Identity architecture
- Deployed IAM/PAM platform
- Access review procedures
IT and cloud maintenance
Administration, support and maintenance of your infrastructure, on-premises or in the cloud.
Detect and respond- Managed service with SLA
- Infrastructure inventory and documentation
- Monthly service report
I need to reduce exposure
Exposure reduction
We discover, prioritise and close the attack surface before an adversary finds it.
CTEM
Continuous threat exposure management: prioritising what an attacker would exploit first.
Prevent- CTEM programme
- Exposure dashboard
- Cycle reports
EASM
Discovery and monitoring of the external attack surface, seen as an attacker sees it.
Prevent- External attack surface inventory
- Continuous alerts
- Exposure report
Vulnerability Management
Vulnerability management programme: scanning, prioritisation, remediation and verification.
Prevent- Vulnerability management programme
- Periodic reports
- Remediation metrics
Continuous pentesting
One-off or continuous penetration testing of networks, applications, cloud, mobile and OT.
Prevent- Pentest report
- Executive summary
- Verification retest
Red Team
Real adversary simulation to measure your organisation's detection and response capability.
Prevent- Red Team report
- Detection and gap map
- Defence improvement plan
Phishing and awareness
Phishing simulations and training so that your staff can recognise scams.
Prevent- Annual awareness programme
- Campaign reports
- Training certificates
I need resilience and continuity
Resilience and continuity
Backup, recovery, high availability and business continuity so that an incident does not bring the organisation to a halt.
Managed backup
Immutable, verified and restorable backups of systems, cloud and SaaS.
Recover- Backup plan
- Managed backup service
- Restore test report
Disaster Recovery
Disaster recovery with defined and tested recovery time and recovery point objectives.
Recover- BIA
- Disaster recovery plan
- Drill report
High availability
Redundant architectures and load balancing so that services never stop.
Recover- High-availability architecture
- Managed load balancing service
- Availability report
Business continuity (ISO 22301)
Business continuity management system: impact analysis, plans and testing.
Recover- BIA
- Continuity and crisis plans
- Testing programme
I need to protect a digital product
Digital product security
Product Security, PSIRT, SBOM, AppSec and Cyber Resilience Act for software vendors, SaaS and connected product manufacturers.
Product Security
Product security programme for software, SaaS and connected devices.
Prevent- Product security programme
- Threat model
- Security-by-design evidence
PSIRT
Product security incident response team and coordinated disclosure.
Prevent- Operational PSIRT
- Disclosure policy
- Security advisory templates
SBOM
Software component inventory and supply chain vulnerability management.
Prevent- SBOM per product and version
- Automated process
- Component vulnerability reports
AppSec
Security for web, API and mobile applications across their entire lifecycle.
Prevent- Review report
- Tools integrated into the pipeline
- Training plan
SecDevOps
Security built into the development and deployment cycle, not bolted on at the end.
Prevent- Secure pipeline
- Guidelines and policy as code
- DevSecOps maturity report
Cyber Resilience Act (CRA)
Adaptation of products with digital elements to the European Cyber Resilience Regulation.
Prevent- Applicability report
- CRA gap assessment
- Adaptation plan and technical documentation
I need to protect key people
Protection of key people
Discreet, continuous digital protection focused on real risk for executives, business families and public figures.
Personal exposure assessment
What information about you and your family is exposed, where, and what risk it poses.
Protect- Private exposure report
- Risk reduction plan
- Confidential debrief session
Digital identity protection
Continuous monitoring and protection of your identity, your accounts and your name online.
Protect- Continuous monitoring service
- Alerts and monthly reports
- Takedown management
Impersonation protection
Prevention of and response to fraud that uses your identity, your voice or your image.
Protect- Anti-impersonation protocol
- Training for the close circle
- Detection and takedown service
Device and account security
Hardening of mobiles, laptops, home networks and personal accounts for the individual and their family.
Protect- Secured devices and accounts
- Personal best-practice guide
- Quarterly reviews
Privacy and reputation
Digital footprint reduction and continuous reputation monitoring.
Protect- Footprint reduction plan
- Reputation monitoring service
- Confidential reports
Confidential crisis response
A discreet team to act in the event of extortion, leaks, online harassment or a reputational crisis.
Protect- Confidential response retainer
- Private executive report
- Prevention plan
I need to manage and harden mobile devices
Secure mobility and devices
Management, hardening, VPN and encryption for mobile fleets with Samsung SDS EMM On-Prem, deployed and operated by Bomontec.
Enterprise mobility management (EMM) On-Prem
Inventory, policies, applications and compliance for mobile fleets from a console under your control.
Protect- EMM architecture
- Deployed platform and policies
- Migration and training plan
VPN and secure communications
Always-on and per-app tunnels managed from the EMM, with dual-tunnel architectures.
Protect- Secure communications architecture
- Deployed VPN policies
- Operating procedures
Data and device encryption
Encryption at rest and in transit, Knox DualDAR, key management and secure wipe.
Protect- Encryption policy
- Deployed configuration
- Audit evidence
Migration from Omnissa / Workspace ONE
Assessment, architecture, pilot and Fast-Track migration to Samsung SDS EMM before end of support.
Protect- Assessment report
- Migration plan
- Migrated and documented platform
How we work
A clear methodology to turn uncertainty into control.
- 01
Discover
We get to know your business, environment, risks and priorities.
- 02
Analyse
We assess maturity, exposure, compliance and real capabilities.
- 03
Design
We define strategy, roadmap, architecture and action plan.
- 04
Implement
We deliver controls, processes, technology and evidence.
- 05
Operate
We monitor, respond and support continuous improvement.
- 06
Optimise
We measure results, reduce risk and evolve capabilities.
Next step
Not sure where to start?
Tell us your situation and we'll tell you which risk to reduce first, which capability to build and how to prove it.










